setup-devadvokit

Pass

Audited by Gen Agent Trust Hub on Sep 29, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONPROMPT_INJECTIONPERSISTENCE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill creates a surface for indirect prompt injection by gathering unsanitized user input and writing it directly to a persistent file (~/.devadvokit.md) that is explicitly intended to be read by other skills. This could allow malicious instructions to be injected into the agent's future context.
  • Ingestion points: User answers to the 14 identity questions and the content library collection in SKILL.md.
  • Boundary markers: Absent; user input is placed directly into markdown fields and tables.
  • Capability inventory: File-write capability to create and modify ~/.devadvokit.md.
  • Sanitization: Absent; no validation or escaping of user input is implemented.
  • [PROMPT_INJECTION]: The skill includes a directive to read an external file (../../shared/ai-antipatterns.md) and 'silently rewrite' output based on its content while hiding this step from the user. This instruction concealment and reliance on content outside the skill's defined folder can override standard behavior.
  • [PERSISTENCE]: The skill establishes persistence by creating a hidden configuration file in the user's home directory to maintain context and history across different sessions and skills.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 29, 2026, 12:38 PM